Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72649— Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution

Quick assessment

Affected
Elastic Elasticsearch
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Elasticsearch 机器学习组件中存在的不可信数据反序列化漏洞(CWE-502)可能导致通过对象注入(CAPEC-586)实现远程代码执行。一个特制的已训练模型工件可能触发由攻击者控制的逻辑执行,且其系统调用权限范围远超预期。利用该漏洞需要拥有足够权限以创建和部署已训练模型的经过身份验证的用户。

CVSS 8.8 · High

Affected Version Matrix 3

VendorProduct Version RangeStatus
Elastic Elasticsearch 8.0.0≤ 8.19.19 affected
9.0.0≤ 9.4.4 affected
9.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-72649

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution
Source: CVE Program / CVE List V5
Vulnerability Description
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Elastic Elasticsearch 8.0.0 ~ 8.19.19 -

II. Public POCs for CVE-2026-72649

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72649

登录查看更多情报信息。

Other References for CVE-2026-72649 (1)

Same Patch Batch · Elastic · 2026-09-01 · 20 CVEs total

CVE-2026-63137 8.3 HIGH Incorrect Authorization in Kibana Leading to Privilege Escalation
CVE-2026-78592 7.3 HIGH Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori
CVE-2024-14047 7.2 HIGH Improper Link Resolution Before File Access ('Link Following') in Winlogbeat Leading to Ar
CVE-2026-33465 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-63138 6.5 MEDIUM Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Infor
CVE-2026-78608 6.5 MEDIUM Missing Authorization in Kibana Leading to Information Disclosure
CVE-2026-72654 6.5 MEDIUM Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure
CVE-2026-72628 6.5 MEDIUM Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service
CVE-2026-72652 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-72644 6.5 MEDIUM Uncaught Exception in Kibana Leading to Denial of Service
CVE-2026-72682 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-78605 5.9 MEDIUM Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch L
CVE-2026-78607 5.4 MEDIUM Missing Authorization in Elasticsearch Leading to Information Disclosure
CVE-2026-72641 5.4 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data
CVE-2026-56143 4.9 MEDIUM Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of
CVE-2026-72633 4.3 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitorin
CVE-2026-78603 4.3 MEDIUM Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Met
CVE-2026-78597 4.3 MEDIUM Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation
CVE-2026-78606 4.2 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and De

IV. Related Vulnerabilities

V. Comments for CVE-2026-72649

No comments yet


Leave a comment